Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-6780

21
FAUCET Score

CVE-2023-6780 is an integer overflow vulnerability in the glibc library's __vsyslog_internal function, affecting glibc versions 2.37 and newer, including Fedora distributions. This flaw arises when syslog or vsyslog functions process excessively long messages, leading to incorrect buffer size calculations and undefined behavior. Rated Medium (CVSS 5.3), it has a low impact on availability and requires no user interaction, but its network-based attack vector makes it concerning. While no public exploits or Metasploit modules are available, and it's not on the KEV catalog, media coverage indicates potential for privilege escalation on major Linux distributions.

Impacted Technologies

VendorProductVersion(s)CPE
All Versions ImpactedCPE match
cpe:2.3:o:fedoraproject:fedora:*:*:*:*:*:*:*:*
>= 2.37, < 2.39CPE matchmatch criteria
cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*
38CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
39CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.71%
Probability of exploitation in next 30 days
EPSS Percentile
84.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0271 is in the 77th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

microsoftpatch availablevia msrc
Product: 18299-17084Fixed in: 2.38-6
microsoftpatch availablevia msrc
Product: 19758-17084Fixed in: 2.38-6
microsoftpatch availablevia msrc
Product: azl3 glibc 2.38-6 on Azure Linux 3.0Fixed in: 2.38-6
microsoftpatch availablevia msrc
Product: azl3 glibc 2.38-10 on Azure Linux 3.0Fixed in: 2.38-6
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 2.38-6
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 2.38-6

Vendor Advisories (3)

microsoft2024-Jun/CVE-2023-6780

CVE-2023-6780

Jun 11, 2024
redhatCVE-2023-6780Low

glibc: integer overflow in __vsyslog_internal()

Jan 30, 2024
microsoft2024-Jan/CVE-2023-6780Moderate

Glibc: integer overflow in __vsyslog_internal()

Jan 9, 2024

References

cert-portal.siemens.com / productcert/html/ssa-082556.html
security.netapp.com / advisory/ntap-20250207-0010
packetstormsecurity.com / files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html
ExploitThird Party AdvisoryVDB Entry
access.redhat.com / security/cve/CVE-2023-6780
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
seclists.org / fulldisclosure/2024/Feb/3
ExploitMailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ
Mailing List
security.gentoo.org / glsa/202402-01
Third Party Advisory
openwall.com / lists/oss-security/2024/01/30/6
ExploitMailing List
qualys.com / 2024/01/30/cve-2023-6246/syslog.txt
Third Party Advisory